Self-registration
This page helps you decide whether people can create their own accounts, and how they prove their email address when they do.
Self-registration is a user creating their own account, from the Register link on the sign-in page, instead of an administrator creating it. It’s off in a new installation, so only your administrators create users until you turn it on.
Turn on self-registration
Section titled “Turn on self-registration”Email verification is on in a new installation, so a new account’s address is proven before the account exists: the person who registers gets a link by email, and chooses their password only after following it. That needs email, so set it up first.
-
Set up email under Admin, Email - SMTP, and send yourself a test message from the Send test email tab.
-
Open Admin, General.
-
Turn on User self registration enabled, leave User self registration requires email verification on, and click Save.
The sign-in page now shows a Register link. If it doesn’t, email isn’t set up yet, and Admin, General shows a warning under User self registration requires email verification saying registration is unavailable. To turn self-registration off again, turn off User self registration enabled on the same page. Only administrators can then create users. User self registration requires email verification keeps its value meanwhile, greyed out, so turning self-registration back on brings back the choice you made.
Who can register
Section titled “Who can register”| Setting | Default |
|---|---|
| User self registration enabled | Off |
| User self registration requires email verification | On |
While User self registration enabled is off, the sign-in page shows no Register link and the registration pages lead to a not-found page. Turning it on opens registration when email is set up or email verification is off.
With User self registration requires email verification on, people prove their address first, as With email verification describes. With it off, they don’t, as Without email verification describes.
Email verification needs email. While it’s on and email isn’t set up, nobody can register: the sign-in page shows no Register link and the registration form leads to a not-found page, just as the forgot-password page does without email. Meanwhile Admin, General shows a warning saying so, under User self registration requires email verification. Set up email, or turn email verification off, to open registration.
Without email verification
Section titled “Without email verification”The registration form asks for an email address and a password, twice. The password must meet the Password policy on Admin, General. When the form is sent, the account is created at once, with its address not verified, and the page says “Your account has been created.” When email is set up, the user also gets a “Welcome!” email.
An address that already has an account is refused with “Apologies, but this email address is already registered.”
This form appears only while email verification is off. It works with or without email set up.
With email verification
Section titled “With email verification”The registration form asks for the email address alone, and every well-formed address gets the same “Check your email” page, whether or not it has an account. What happens next travels by email:
- A new address gets an “Activate your account” email with a link, valid for 5 minutes. Following it opens a “Choose your password” form, which can be sent for 5 minutes more. Sending it creates the account, with its address verified.
- An address with an account gets a “You already have an account” email instead, pointing at the forgot-password page, when the account is enabled and its address verified, the same rule password recovery uses. Any other account gets nothing.
- An address with a registration still pending gets nothing. Its link is still the one that works. Once both 5-minute windows have passed, registering again sends a new link.
Following the link creates nothing by itself. Only sending the form does, so a mail scanner or link previewer that opens the link can’t complete a registration, and someone who registers an address that isn’t theirs never gets to choose its password.
If the address gains an account before the form is sent, because an administrator created one, the registration is refused and discarded. While self-registration is off, the registration page and every link already sent lead to a not-found page. Turning email off doesn’t stop a link already sent: following it needs no email, so it still creates the account.
An expired or used link shows “Unable to activate the account. The verification code appears to be expired.” The person registers again to get a new one. While registration is unavailable because email isn’t set up, the page leaves out its link to the registration form.
What a new account has
Section titled “What a new account has”A user who registers gets what every new user gets: the authserver:manage-account permission, so they can manage their own account in the admin console’s Account pages, and nothing else. See Users and groups.
Limits and the audit log
Section titled “Limits and the audit log”An address can register 5 times every 5 minutes, whether or not the rate limiter is on. With it on, an IP address can register 20 times, and following links and sending the password form is limited per IP address. Past that, the page shows “Too many attempts”: see Too many attempts or 429.
Every registration with email verification leaves a requested_registration entry in the audit log, whose outcome says what it led to, such as link_issued or notice_issued. The address is recorded only as a digest. An account created leaves created_user, an activated one activated_account, and a refused link failed_account_activation_code.